Host Header Injection Attack | Authentication Bypass

Описание к видео Host Header Injection Attack | Authentication Bypass

During this video we look at a simple scenario where an attacker exploits HTTP Host header Injection vulnerability to bypass application access control to perform administrative action without having valid admin credentials.

Web Security Academy | Lab: Host header authentication bypass
https://portswigger.net/web-security/...

NOTE: This video is made ONLY for educational purposes and to help developers and security researchers to enhance their security knowledge. Therefore, allowing them remediate potential vulnerabilities in their OWN applications.

Twitter:   / tracethecode  

Комментарии

Информация по комментариям в разработке